← Back

CVE-2026-59688

nvd nist
Published: Jul 27, 2026Modified: Aug 11, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.7 / Impact: 6.0
Source: security@progress.com (Secondary)

Description

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

Affected (5)

4 products
Ecs Connection Manager
Loadmaster
Moveit Web Application Firewall
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.2.63.3
Before 7.2.63.3
Progress
Before 7.2.54.19
From 7.2.55.0 to 7.2.63.3
Before 7.2.63.3

Timeline

No history available yet.